Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6w4p-96gh-fgfp

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload the file outside of the restricted directory.

BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload the file outside of the restricted directory.

EPSS

Процентиль: 64%
0.00465
Низкий

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.7
nvd
почти 5 лет назад

BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload the file outside of the restricted directory.

EPSS

Процентиль: 64%
0.00465
Низкий

Дефекты

CWE-22